Creator ยท trailofbits
Last updated ยท Sep 1, 2026
Performs security-focused differential review of code changes. Adapts analysis depth to codebase size, uses git blame for context, calculates blast radius by counting callers, checks test coverage of modified code, and generates a markdown report. Use when reviewing a PR, commit,
Sandbox only
Install targets
Codex install prompt
Install the "differential-review" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/differential-review/skills/differential-review. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: Performs security-focused differential review of code changes. Adapts analysis depth to codebase size, uses git blame for context, calculates blast radius by counting callers, checks test coverage of modified code, and generates a markdown report. Use when reviewing a PR, commit, or diff for security vulnerabilities, checking whether a change re-introduces a previously fixed bug, asking what else a change could break, or finding which modified code has no test covering it. After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {"event_id":"install_<unique-id>","skill_slug":"trailofbits-differential-review","task":"Install differential-review","agent":"codex","outcome":"success","install_used":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.Supply asset profile
Deep research, source comparison, literature review, RAG, knowledge search, and reports.
Scenario
Research agents
I need my agent to research a topic, compare sources, and produce a concise report.
Agent fit
Claude Code + CLI + Codex
Codex, Claude Code, Cursor, CLI, or custom agents.
Install
Ready
npx skills add trailofbits/skills --skill differential-review
Maintenance
fresh
11d since push
Risk
Needs review
Financial research output is not financial advice; require human review before any live investment decision
GitHub quality
6.9K
86/100 Quality ยท 83/100 Trust
Coverage tags
Review notes
Financial research output is not financial advice; require human review before any live investment decision ยท Financial research output is not financial advice; require human review before any live investment decision.
Agent adoption scorecard
These scores combine public repository metadata, OpenAgentSkill review signals, maintenance freshness, and install readiness. They are a shortlist signal, not a replacement for human review.
Quality
ExcellentHigh-confidence pick with strong adoption and healthy maintenance signals.
Trust
Sandbox onlyUseful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
Audit
Needs reviewA machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
OpenAgentSkill Trust Score v5
Run only in a sandbox and compare close alternatives before using it for real work.
Stars
6.9K GitHub stars
Repo activity
6.9K stars, 590 forks
Maintenance
11d since push
License
CC-BY-SA-4.0
Install
npx skills add trailofbits/skills --skill differential-review
Install safety
Agent-readable metadata
Use this block or the embedded JSON to decide whether an agent should install this skill, choose an alternative, or ask for human review first.
Suited tasks
Suited agents
Install decision
Trust and risk
Outcome loop
Install command
npx skills add trailofbits/skills --skill differential-reviewDo not use when
Agent safety v2
Sparse or mixed signals. Useful for discovery, but not for autonomous installation.
Test manually in an isolated workspace and compare against safer alternatives.
high
Skill metadata references terminal, CLI, shell, subprocess, or command execution workflows.
medium
Skill likely fetches remote pages, APIs, repositories, or external services.
medium
Skill may read or write project files, documents, generated artifacts, or local workspace state.
high
Skill metadata references credentials, tokens, environment variables, or secret-bearing workflows.
Agent resolve plan
The Resolve API returns the selected skill, alternatives, safety policy, audit notes, install target, and copy-paste prompt an agent can follow without scraping this page.
Open JSON
/api/agent/resolve?task=Use%20differential-review%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve text
/api/agent/resolve?task=Use%20differential-review%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
Install handoff
/api/skills/trailofbits-differential-review/install
Agent should check
Copy prompt
Task: Use differential-review in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20differential-review%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/trailofbits-differential-review/install
Install command: npx skills add trailofbits/skills --skill differential-review
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent handoff
Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.
Install handoff
/api/skills/trailofbits-differential-review/install
LLM text format
/api/skills/trailofbits-differential-review/install?format=text
Find alternatives
/api/skills/search?q=differential-review&limit=3
Agent prompt
Use differential-review for this task. Review https://www.openagentskill.com/api/skills/trailofbits-differential-review/install, then install with: npx skills add trailofbits/skills --skill differential-reviewRegistry metadata
This page exposes the same decision, trust, audit, use-case, and install signals through the Registry API, so agents can rank this skill without scraping the UI.
Manifest
/api/registry/manifest/trailofbits-differential-review
LLM text
/api/registry/manifest/trailofbits-differential-review?format=text
Install alias
/api/registry/install/trailofbits-differential-review
Recommend
/api/registry/recommend?task=Use%20differential-review%20in%20an%20agent%20workflow&limit=3
Agent fit
Research agents
Use-case tags
Platforms
Claude Code
Audit report
A machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
Agent decision cockpit
Use this as a leading candidate, then validate the README and install path in your own agent stack.
Role in stack
Primary pick
Primary fit
Research agents
Trust label
Production-ready
Install path
Command ready
Use when
Evidence
review first
Implementation path
Trust profile
Useful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
GitHub adoption
PASS6.9K GitHub stars
Stars/forks activity
PASS6.9K stars, 590 forks; issue activity unavailable in current metadata
Recent maintenance
PASS11d since push
License clarity
PASSCC-BY-SA-4.0
Good signals
Review before install
Recommended action
Run only in a sandbox and compare close alternatives before using it for real work.
Quality profile
High-confidence pick with strong adoption and healthy maintenance signals.
Workflow fit
Investigate faster
I need my agent to research a topic, compare sources, and produce a concise report.
Analyze markets
I need my agent to analyze markets, financial data, filings, portfolios, and quant strategies.
Manage repositories
I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.
Workflow fit
Turn skills into distribution
A workflow for turning newly indexed skills into SEO briefs, social drafts, comparison pages, and reusable publishing workflows.
Ingest, retrieve, and cite
A workflow for document-heavy agents that ingest files, create searchable knowledge, retrieve relevant context, and answer with grounded sources.
Operate and verify web apps
A workflow for agents that navigate products, fill forms, take screenshots, and verify real user flows across web applications.
Alternative shortlist
Similar skills that may fit this task.
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
๐ต๏ธโโ๏ธ Collect a dossier on a person by username from 3000+ sites
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
Infisical is the open-source platform for secrets, certificates, and privileged access management.
--- name: differential-review description: "Performs security-focused differential review of code changes. Adapts analysis depth to codebase size, uses git blame for context, calculates blast radius by counting callers, checks test coverage of modified code, and generates a markdown report. Use when reviewing a PR, commit, or diff for security vulnerabilities, checking whether a change re-introduces a previously fixed bug, asking what else a change could break, or finding which modified code has no test covering it." allowed-tools: Read Write Grep Glob Bash ---
# Differential Security Review
Security-focused code review for PRs, commits, and diffs.
## Core Principles
1. **Risk-First**: Focus on auth, crypto, value transfer, external calls 2. **Evidence-Based**: Every finding backed by git history, line numbers, attack scenarios 3. **Adaptive**: Scale to codebase size (SMALL/MEDIUM/LARGE) 4. **Honest**: Explicitly state coverage limits and confidence level 5. **Output-Driven**: Always generate comprehensive markdown report file
---
## Rationalizations (Do Not Skip)
| Rationalization | Why It's Wrong | Required Action | |-----------------|----------------|-----------------| | "Small PR, quick review" | Heartbleed was 2 lines | Classify by RISK, not size | | "I know this codebase" | Familiarity breeds blind spots | Build explicit baseline context | | "Git history takes too long" | History reveals regressions | Never skip Phase 1 | | "Blast radius is obvious" | You'll miss transitive callers | Calculate quantitatively | | "No tests = not my problem" | Missing tests = elevated risk rating | Flag in report, elevate severity | | "Just a refactor, no security impact" | Refactors break invariants | Analyze as HIGH until proven LOW | | "I'll explain verbally" | No artifact = findings lost | Always write report |
---
## Quick Reference
### Codebase Size Strategy
| Codebase Size | Strategy | Approach | |---------------|----------|----------| | SMALL (<20 files) | DEEP | Read all deps, full git blame | | MEDIUM (20-200) | FOCUSED | 1-hop deps, priority files | | LARGE (200+) | SURGICAL | Critical paths only |
### Risk Level Triggers
| Risk Level | Triggers | |------------|----------| | HIGH | Auth, crypto, external calls, value transfer, validation removal | | MEDIUM | Business logic, state changes, new public APIs | | LOW | Comments, tests, UI, logging |
---
## Workflow Overview
``` Pre-Analysis โ Phase 0: Triage โ Phase 1: Code Analysis โ Phase 2: Test Coverage โ โ โ โ Phase 3: Blast Radius โ Phase 4: Deep Context โ Phase 5: Adversarial โ Phase 6: Report ```
---
## Decision Tree
**Starting a review?**
``` โโ Need detailed phase-by-phase methodology? โ โโ Read: methodology.md โ (Pre-Analysis + Phases 0-4: triage, code analysis, test coverage, blast radius) โ โโ Analyzing HIGH RISK change? โ โโ Read: adversarial.md โ โ (Phase 5: Attacker modeling, exploit scenarios, exploitability rating) โ โโ Or delegate to: differential-review:adversarial-modeler agent โ (Autonomous attacker modeling with concrete exploit scenarios) โ โโ Writing the final report? โ โโ Read: reporting.md โ (Phase 6: Report structure, templates, formatting guidelines) โ โโ Looking for specific vulnerability patterns? โ โโ Read: patterns.md โ (Regressions, reentrancy, access control, overflow, etc.) โ โโ Quick triage only? โโ Use Quick Reference above, skip detailed docs ```
---
## Agents
**`differential-review:adversarial-modeler`** โ Models attacker perspectives and builds exploit scenarios for HIGH RISK code changes. Follows the 5-step adversarial methodology (attacker model, attack vectors, exploitability rating, exploit scenario, baseline cross-reference) and produces structured vulnerability reports. Delegate to this agent when Phase 5 analysis is needed on high-risk changes, passing that full namespaced name as `subagent_type` โ a bare `adversarial-modeler` is unregistered and the dispatch fails at runtime.
---
## Quality Checklist
Before delivering:
- [ ] All changed files analyzed - [ ] Git blame on removed security code - [ ] Blast radius calculated for HIGH risk - [ ] Attack scenarios are concrete (not generic) - [ ] Findings reference specific line numbers + commits - [ ] Report file generated - [ ] User notified with summary
---
## Integration
**audit-context-building skill:** - Pre-Analysis: Build baseline context - Phase 4: Deep context on HIGH RISK changes
**issue-writer skill:** - Transform findings into formal audit reports - Command: `issue-writer --input DIFFERENTIAL_REVIEW_REPORT.md --format audit-report`
---
## Example Usage
### Quick Triage (Small PR) ``` Input: 5 file PR, 2 HIGH RISK files Strategy: Use Quick Reference 1. Classify risk level per file (2 HIGH, 3 LOW) 2. Focus on 2 HIGH files only 3. Git blame removed code 4. Generate minimal report Time: ~30 minutes ```
### Standard Review (Medium Codebase) ``` Input: 80 files, 12 HIGH RISK changes Strategy: FOCUSED (see methodology.md) 1. Full workflow on HIGH RISK files 2. Surface scan on MEDIUM 3. Skip LOW risk files 4. Complete report with all sections Time: ~3-4 hours ```
### Deep Audit (Large, Critical Change) ``` Input: 450 files, auth system rewrite Strategy: SURGICAL + audit-context-building 1. Baseline context with audit-context-building 2. Deep analysis on auth changes only 3. Blast radius analysis 4. Adversarial modeling 5. Comprehensive report Time: ~6-8 hours ```
---
## When NOT to Use This Skill
- **Greenfield code** (no baseline to compare) - **Documentation-only changes** (no security impact) - **Formatting/linting** (cosmetic changes) - **User explicitly requests quick summary only** (they accept risk)
For these cases, use standard code review instead.
---
## Red Flags (Stop and Investigate)
**Immediate escalation triggers:** - Removed code from "security", "CVE", or "fix" commits - Access control modifiers removed (onlyOwner, internal โ external) - Validation removed without replacement - External calls added without checks - High blast radius (50+ callers) + HIGH risk change
These patterns require adversarial analysis even in quick triage.
---
## Tips for Best Results
**Do:** - Start with git blame for removed code - Calculate blast radius early to prioritize - Generate concrete attack scenarios - Reference specific line numbers and commits - Be honest about coverage limitations - Always generate the output file
**Don't:** - Skip git history analysis - Make generic findings without evidence - Claim full analysis when time-limited - Forget to check test coverage - Miss high blast radius changes - Output report only to chat (file required)
---
## Supporting Documentation
- **[methodology.md](methodology.md)** - Detailed phase-by-phase workflow (Phases 0-4) - **[adversarial.md](adversarial.md)** - Attacker modeling and exploit scenarios (Phase 5) - **[reporting.md](reporting.md)** - Report structure and formatting (Phase 6) - **[patterns.md](patterns.md)** - Common vulnerability patterns reference
---
**For first-time users:** Start with [methodology.md](methodology.md) to understand the complete workflow.
**For experienced users:** Use this page's Quick Reference and Decision Tree to navigate directly to needed content.
Decision snapshot
6,876 GitHub stars
Audit
Install and adoption review
Agent-proven evidence
Outcome reports after resolve, review, install, and one narrow run.
No agent outcome data yet. The first agent run can report success, setup needs, risk blocks, failure, or not-relevant through /api/agent/outcome.
Install
Free and open source. Review the report before installing into production agents.
Growth loop
Scenario-led draft for differential-review, ready for a manual X post.
differential-review: Performs security-focused differential review of code changes. Adapts analysis depth to codeb... 6.9K stars https://www.openagentskill.com/skills/trailofbits-differential-review?ref=x
Listing + install path for differential-review: https://www.openagentskill.com/skills/trailofbits-differential-review?ref=x Install: npx skills add trailofbits/skills --skill differential-review
Listing source
This listing was indexed from public sources and is not marked official until a maintainer claim is approved.
Attribution links to the public repository or creator profile. Creators can claim the listing to update ownership signals.
Claim this skillOwner claim
This Registry indexed listing is attributed to trailofbits but is not marked official yet. Claim it to add a verified owner signal and make future launch, install, and audit updates easier to trust.
Creator backlink kit
Show the canonical listing, current trust and audit signals, and real Agent-Proven evidence where developers evaluate the repository.
[](https://www.openagentskill.com/skills/trailofbits-differential-review?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/trailofbits-differential-review?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/trailofbits-differential-review/audit)
[](https://www.openagentskill.com/skills/trailofbits-differential-review?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)trailofbits
@trailofbits
Share whether this skill looks useful for your agent workflow. Aggregated feedback improves rankings over time.
Sandbox only
Wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
16.3K StarsMaigret
๐ต๏ธโโ๏ธ Collect a dossier on a person by username from 3000+ sites
32.9K StarsNuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
29.2K StarsInfisical
Infisical is the open-source platform for secrets, certificates, and privileged access management.
27.4K StarsPermission surface
shell or command execution, filesystem or document access
Agent outcomes
No agent outcome data yet
Docs
Strong README/SKILL.md context
Risk summary
Install readiness